gawk --lint
Warns about constructs that are dubious or nonportable to other awk implementations.
⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.
This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.
Warns about constructs that are dubious or nonportable to other awk implementations.
copyright: — Astrée automatically proves the absence of runtime errors and invalid concurrent behavior in C/C++ applications. It is sound for floating-point computations, very fast, and exceptionally precise. The analyzer also checks for MISRA/CERT/CWE/Adaptive Autosar coding rules and supports…
Bounded model-checker for C programs, user-defined assertions, standard assertions, several coverage metric analyses.
Clang-based C++ linter tool with the (limited) ability to fix issues, too.
Qt-oriented static code analyzer based on the Clang framework. clazy is a compiler plugin which allows clang to understand Qt semantics. You get more than 50 Qt related compiler warnings, ranging from unneeded memory allocations to misusage of API, including fix-its for automatic refactoring.
A defect database and viewer extension for the Clang Static Analyzer with web GUI.
A tool for configurable software verification of C programs. The name CPAchecker was chosen to reflect that the tool is based on the CPA concepts and is used for checking software programs.
Static analysis of C/C++ code.
copyright: — Measure, query and visualize your code and avoid unexpected issues, technical debt and complexity.
Automated C++ checker that follows Google's style guide.
Complexity and quality metrics for C and C preprocessor code.
ESBMC is an open source, permissively licensed, context-bounded model checker based on satisfiability modulo theories for the verification of single- and multi-threaded C/C++ programs.
Finds possible security weaknesses.
A sound and extensible static analyzer for C code.
The GCC compiler has static analysis capabilities since version 10. This option is only available if GCC was configured with analyzer support enabled. It can also output its diagnostics to a JSON file in the SARIF format (from v13).
A static analyzer for the analysis of multi-threaded C programs. Its primary focus is the detection of data races, but it also reports other runtime errors, such as buffer overflows and null-pointer dereferences.
copyright: — Enterprise-grade static analysis for embedded software. Supports MISRA, CERT, and AUTOSAR coding standards.
A dynamic symbolic execution engine built on top of the LLVM compiler infrastructure. It can auto-generate test cases for programs such that the test cases exercise as much of the program as possible.
copyright: — A tool suite including static analysis (TBVISION) to various standards including MISRA C & C++, JSF++ AV, CWE, CERT C, CERT C++ & Custom Rules.
copyright: — Static analysis for C/C++. Runs natively under Windows/Linux/MacOS. Analyzes code for virtually any platform, supporting C11/C18 and C++17.
A LLVM-based static analysis framework which comes with a taint and type state analysis.
copyright: — Identifies run-time errors, concurrency issues, security vulnerabilities, and other defects in C and C++ embedded software.
copyright: — Provide code verification that proves the absence of overflow, divide-by-zero, out-of-bounds array access, and certain other run-time errors in C and C++ source code.
Frontend to drive the Clang Static Analyzer built into Clang via a regular build.
Annotation-assisted static program checker.
A static tool that enables scalable and precise interprocedural dependence analysis for C and C++ programs.
copyright: — Exhaustive detection of coding errors and their associated security vulnerabilities. This encompasses a sound undefined behavior detection (buffer overflows, out-of-bounds array accesses, null-pointer dereferences, use-after-free, divide-by-zeros, uninitialized memory accesses, signed…
An organization for the development of analyzers (diagnostics and code fixes) using the .NET Compiler Platform.
A C# architecture test library to specify and assert architecture rules in C# for automated testing.
copyright: — Designite supports detection of various architecture, design, and implementation smells, computation of various code quality metrics, and trend analysis.
A Roslyn analyzer to enforce some good practices in C# in terms of design, usage, security, performance, and style.
copyright: — Measure, query and visualize your code and avoid unexpected issues, technical debt and complexity.
Puma Scan provides real time secure code analysis for common vulnerabilities (XSS, SQLi, CSRF, LDAPi, crypto, deserialization, etc.) as development teams write code in Visual Studio.
A collection of 190+ analyzers and 190+ refactorings for C#, powered by Roslyn.
These Roslyn analyzers allow you to produce Clean Code that is safe, reliable, and maintainable by helping you find and correct bugs, vulnerabilities, and code smells in your codebase.
A linter for Clojure code that sparks joy. It informs you about potential errors while you are typing.
copyright: — Static security code analysis for ColdFusion or CFML code. Designed to work within a CI pipeline or from the developers terminal.
A static code analysis tool for Crystal.
An opinionated, community-driven set of lint rules for Dart and Flutter projects. Like pedantic but stricter
A Delphi IDE package providing on-the-fly code analysis and linting, powered by SonarDelphi.
copyright: — A free IDE Plugin for static code analysis. A Pro edition includes a command line tool for automation purposes.
copyright: — A static code analysis tool with numerous reports. A free Lite version is available with limited reporting.
copyright: — IDE plugin for code analysis. Includes a subset of Pascal Analyzer reporting capabilities and is available for Delphi versions 2007 and later.
Delphi static analyzer for the SonarQube code quality platform.
D-Scanner is a tool for analyzing D source code.
A static code analysis tool with a focus on code consistency and teaching.
Mix tasks to simplify use of Dialyzer in Elixir projects.
Analyzes whole Elm projects, with a focus on shareable and custom rules written in Elm that add guarantees the Elm compiler doesn't give you.
The DIALYZER, a DIscrepancy AnaLYZer for ERlang programs. Dialyzer is a static analysis tool that identifies software discrepancies, such as definite type errors, code that has become dead or unreachable because of programming error, and unnecessary tests, in single Erlang modules or entire (sets…
Erlang Style Reviewer.
F# source code formatter.
Lint tool for F#.
A collection of F# analyzers, built with the FSharp.Analyzers.SDK.
Fortran linter, inspired by (and built on) Ruff, and based on community best practices. Supports latest Fortran (2023) standard.
Auto-formatter for modern fortran source code, written in Python. Fprettify is a tool that provides consistent whitespace, indentation, and delimiter alignment in code, including the ability to change letter case and handle preprocessor directives, all while preserving revision history and tested…
Find inefficiently packed structs.
Checks whether HTTP response body is closed.
Reports potentially duplicated code.
Get info on length of functions in a Go package.
Reports variables that may have been unintentionally shadowed.
Go source code linter that maintains checks which are currently not implemented in other linters.
Package ast declares the types used to represent syntax trees for Go packages.
Go AST (Abstract Syntax Tree) based static analysis tool with Rego.
Finds repeated strings that could be replaced by a constant.
Calculate cyclomatic complexities of functions in Go source code.
Checks if the code is properly formatted and could not be further simplified.
Enforce a stricter format than gofmt, while being backwards-compatible. That is, gofumpt is happy with a subset of the formats that gofmt is happy with. The tool is a fork of gofmt as of Go 1.19, and requires Go 1.18 or later. It can be used as a drop-in replacement to format your Go code, and…
Checks missing or unreferenced package imports.
Fast linters runner for Go. It aggregates multiple Go linters and provides a unified configuration, caching, and output format. Alternative to Go Meta Linter.
Inspects source code for security problems by scanning the Go AST.
Syntactic and semantic analysis similar to the Go compiler.
Govulncheck reports known vulnerabilities that affect Go code. It uses static analysis of source code or a binary's symbol table to narrow down reports to only those that could affect the application. By default, govulncheck makes requests to the Go vulnerability database at https://vuln.go.dev.…
Vulnerability scanner written in Go which uses the data provided by OSV.dev. Developed by Google to scan dependencies across multiple languages and package managers for known vulnerabilities. Supports container scanning, license scanning, and guided remediation. Works with lockfiles, SBOMs, and…
Finds slice declarations that could potentially be preallocated.
A tool for posting review comments from any linter in any code hosting service.
Fast, configurable, extensible, flexible, and beautiful linter for Go. Drop-in replacement of golint.
Go static analysis that specialises in finding bugs, simplifying code and improving performance.
Show location of test failures from the stdlib testing module.
Detect redundant type conversions.
Find unused function parameters.
Enforces empty lines at the right places.
A static analysis tool for Groovy source code, enabling monitoring and enforcement of many coding standards and best practices.
HLint is a tool for suggesting possible improvements to Haskell code.
Liquid Haskell is a refinement type checker for Haskell programs.
Stan is a command-line tool for analysing Haskell projects and outputting discovered vulnerabilities in a helpful way with possible solutions for detected problems.
A tool for detecting dead exports or package imports in Haskell code.
A static analysis tool to help developers write Haxe code that adheres to a coding standard.
Pluggable type-checking for Java. This is not just a bug-finder, but a verification tool that gives a guarantee of correctness. It comes with 27 pre-built type systems, and it enables users to define their own type system; the manual lists over 30 user-contributed type systems.
Checking Java source code for adherence to a Code Standard or set of validation rules (best practices).
Calculates Chidamber and Kemerer object-oriented metrics by processing the source Java files.
An industrial-strength dataflow framework for Java. The Dataflow Framework is used in the Checker Framework, Google’s Error Prone, Uber’s NullAway, Meta’s Nullsafe, and in other contexts. It is distributed with the Checker Framework.
copyright: — DesigniteJava supports detection of various architecture, design, and implementation smells along with computation of various code quality metrics.
copyright: — Diffblue is a software company that provides AI-powered code analysis and testing solutions for software development teams. Its technology helps developers automate testing, find bugs, and reduce manual labor in their software development processes. The company's main product,…
Doop is a declarative framework for static analysis of Java/Android programs, centered on pointer analysis algorithms. Doop provides a large variety of analyses and also the surrounding scaffolding to run an analysis end-to-end (fact generation, processing, statistics, etc.).
Catch common Java mistakes as compile-time errors.
A plugin for FindBugs with additional bug detectors.
Detects and forbids invocations of specific method/class/field (like reading from a text stream without a charset). Maven/Gradle/Ant compatible.
Reformats Java source code to comply with Google Java Style
copyright: — Comes bundled with a lot of inspections for Java and Kotlin and includes tools for refactoring, formatting and more.
copyright: — Measure, query and visualize your code and avoid unexpected issues, technical debt and complexity.
Bounded model-checker for Java (bytecode), verifies user-defined assertions, standard assertions, several coverage metric analyses.
An abstract interpretation-based static analyzer for Java build upon the LiSA framekwork.
Our security focused static analysis tool for Android and Java applications. Mariana Trench analyzes Dalvik bytecode and is built to run fast on large codebases (10s of millions of lines of code). It can find vulnerabilities as code changes, before it ever lands in your repository.
Type-based null-pointer checker with low build-time overhead; an Error Prone plugin.
Combines a few (pre-configured) static analysis tools (checkstyle, PMD, Findbugs, ...).
Identifies and prioritizes God Classes and Highly Coupled classes in Java codebases you should refactor first.
A framework for analyzing and transforming Java and Android applications.
Spoon is a metaprogramming library to analyze and transform Java source code (incl Java 9, 10, 11, 12, 13, 14). It parses source files to build a well-designed AST with powerful analysis and transformation API. Can be integrated in Maven and Gradle.
SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.
Java library for parsing report files from static code analysis. Used by a bunch of Jenkins, Maven and Gradle plugins.
A compiler tool to increase efficiency, reduce size, and provide code warnings in JavaScript files.
copyright: — An analyzer for JavaScript which targets runtime errors and quality issues rather than coding conventions.
A static type checker for JavaScript.
information_source: — The JavaScript Code Quality Tool.
A static security code scanner for Node.js applications powered by libsast and semgrep that builds on the njsscan cli tool. It features a UI with various dashboards about an application's security status.
A static analysis framework for Web Components.
Scanner detecting the use of JavaScript libraries with known vulnerabilities.
squirrelscan is a website QA tool built for coding agents such as Claude Code and Cursor. Its squirrel CLI crawls a live site and runs 260+ audit rules across SEO, performance, security, accessibility, structured data and agent experience, then returns exact source-mapped fixes. Runs from the…
A JavaScript code analyzer for deep, cross-editor language support.
Opinionated but configurable ESLint wrapper with lots of goodies included. Enforces strict and readable code.
Static type inference system to detect bugs and type instabilities.
Static Code Analysis for Julia
Static code analysis for Kotlin code.
A program that reformats Kotlin source code to comply with the common community standard for Kotlin code conventions. A ktfmt IntelliJ plugin is available from the plugin repository. To install it, go to your IDE's settings and select the Plugins category. Click the Marketplace tab, search for the…
An anti-bikeshedding Kotlin linter with built-in formatter.
A tool for linting and static analysis of Lua code.
copyright: — Check MATLAB code files for possible problems.
DrNim combines the Nim frontend with the Z3 proof engine in order to allow verify / validate software written in Nim.
A tool for modular formal verification of correctness properties of single-threaded and multithreaded C and Java programs annotated with preconditions and postconditions written in separation logic. To express rich specifications, the programmer can define inductive datatypes, primitive recursive…
Helps discover good candidates for refactoring.
Fast detection of composer dependency issues.
Dependency analysis tool.
Enforce rules for dependencies between software layers.
Combine PHP_CodeSniffer and PHP-CS-Fixer.
Checks code on every commit.
Adds static analysis to Laravel improving developer productivity and code quality. It is a wrapper around PHPStan.
Mago is a complete toolchain for PHP, written in Rust, designed from the ground up for maximum performance.
This tool checks syntax of PHP files faster than serial check with a fancier output.
Calculates software metrics like cyclomatic complexity for PHP code.
A modern static analyzer from etsy.
Easy to use architecture testing tool for PHP.
Fixes your code according to standards like PSR-1, PSR-2, and the Symfony standard.
Instant PHP quality checks from your console. Analysis of code quality and coding style as well as overview of code architecture and its complexity.
A Static Code Analyzer for PHP.
Suggests a next version according to semantic versioning.
A PHP parser written in PHP.
PHPArkitect helps you to keep your PHP codebase coherent and solid, by permitting to add some architectural constraint check to your workflow. You can express the constraint that you want to enforce, in simple and readable PHP code.
Analyzes PHP source code to generate documentation.
Finds possible bugs in your code.
Calculates and visualizes various code quality metrics.
Helps to detect magic numbers.
A tool for running QA tools (phploc, phpcpd, phpcs, pdepend, phpmd, phpmetrics).
Many tools for PHP static analysis in one container.
PHP Static Analysis Tool - discover bugs in your code without running it!
Static analysis tool for finding type errors in PHP applications.
Instant Upgrades and Automated Refactoring of any PHP 5.3+ code. It upgrades your code for PHP 7.4, 8.0 and beyond. Rector promises a low false-positive rate because it looks for narrowly defined AST (abstract syntax tree) patterns. The main use-case are tackling technical debt in your legacy code…
Reflection library to do Static Analysis for PHP Projects
copyright: — Detect security risks, find bugs and provide actionable metrics for PHP projects.
Tool to detect and correct input validation vulnerabilities in PHP (4.0 or higher) web applications and predicts false positives by combining static analysis and data mining.
An open source parser and code analyzer for PL/SQL and Oracle SQL code.
Critique Perl source code for best-practices.
Perltidy is a Perl script which indents and reformats Perl scripts to make them easier to read. The formatting can be controlled with command line parameters. The default parameter settings approximately follow the suggestions in the Perl Style Guide. Besides reformatting scripts, Perltidy can be…
A lightweight static security analysis tool for modern Perl Apps
Autoflake removes unused imports and unused variables from Python code.
A tool that automatically formats Python code to conform to the PEP 8 style guide. It uses the pycodestyle utility to determine what parts of the code needs to be formatted.
A tool to find common security issues in Python code.
The uncompromising Python code formatter.
Design by contract for Python. Write bug-free code. By adding a few decorators to your code, you get for free tests, static analysis, formal verification, and much more.
A tool for ensuring Python code is secure.
A framework for creating lint rules and corresponding auto-fixes for source code.
Signatures for entire Python programs. Extract the structure, the frame, the skeleton of your project, to generate API documentation or find breaking changes in your API.
Autocompletion/static analysis library for Python.
mbake is a Makefile formatter and linter. It only took 50 years!
Check McCabe complexity.
A static type checker that aims to combine the benefits of duck typing and static typing, frequently used with MonkeyType.
Tool for scanning Python packages for known vulnerabilities. Developed by the Python Packaging Authority (PyPA) and supported by Trail of Bits and Google. Scans Python environments and requirements files to identify vulnerable packages and suggests remediation. Supports GitHub Actions, pre-commit…
A wrapper around pylint, pep8, mccabe and others.
A tool for programmatically detecting common mistakes in Python code, such as references to undefined variables and type errors. It can be extended to add additional rules and perform checks specific to particular functions.
(Formerly pep8) Check Python code against some of the style conventions in PEP 8.
Check Python source files for errors.
Looks for programming errors, helps enforcing a coding standard and sniffs for some code smells. It additionally includes pyreverse (an UML diagram generator) and symilar (a similarities checker).
Pyra is a high-level linter static analyzer for data science applications written in Python, that helps developers identify potential issues in their data science code written in Python, as an extension of Lyra.
A fast, scalable type checker for large Python codebases. Pyre-check has been superseded by Pyrefly, its next iteration.
A fast, incremental type checker and language server for Python, providing IDE features like code navigation, semantic highlighting, and code completion.
Static type checker for Python, created to address gaps in existing tools like mypy.
Rate how well a Python project complies with the best practices of the Python packaging ecosystem, and list issues that could be improved.
A tool based on Facebook's pyre-check to identify potential security issues in Python code identified with taint analysis.
Intelligent Python code quality analyzer with CFG-based cyclomatic complexity analysis, dead code detection, clone detection (Type 1-4), and coupling metrics. Uses tree-sitter for parsing. Written in Go.
A static type analyzer for Python code.
A tool (and pre-commit hook) to automatically upgrade syntax for newer versions of the language.
A tool for refurbishing and modernizing Python codebases. Refurb is heavily inspired by clippy, the built-in linter for Rust.
Fast Python linter, written in Rust. 10-100x faster than existing linters. Compatible with Python 3.10. Supports file watcher.
Python dependency vulnerability scanner designed to enhance software supply chain security by detecting packages with known vulnerabilities. Checks Python dependencies against a database of known security vulnerabilities and provides detailed reports. Supports CI/CD integration and multiple output…
An extremely fast Python type checker written in Rust.
A linter, formatter for finding and removing unused import statements.
The strictest and most opinionated python linter ever.
A command-line tool for archiving, exploring and graphing the complexity of Python source code.
Static Code Analysis for R.
A program slicer and dataflow analyzer for the R programming language. Its slicer allows you to reduce a complicated program just to the parts related for a specific task (e.g., the generation of a single or collection of plots, a significance test, ...). The dataflow analysis provides you with a…
Analyses the source code for R packages and provides best-practice recommendations.
Static Code Analysis for R.
Provides code completion, refactoring, folding, diagnostics (with lintr), and more for R.
Formatting of R source code files and pretty-printing of R code.
Regal is a linter for the policy language Rego. Regal aims to catch bugs and mistakes in policy code, while at the same time helping people learn the language, best practices and idiomatic constructs.
Identify database issues before they hit production.
A static analysis security vulnerability scanner for Ruby on Rails applications.
Help to kill N+1 queries and unused eager loading.
Audit Gemfile.lock for gems with security vulnerabilities reported in Ruby Advisory Database.
The tool to avoid various issues due to inconsistencies and inefficiencies between a database schema and application models.
Lint your ERB or HTML files
Flay analyzes code for structural similarities.
Flog reports the most tortured code in an easy to read pain report. The higher the score, the more pain the code is in.
A code metric tool for Rails projects
Code smell detector for Ruby.
A Ruby static code analyzer, based on the community Ruby style guide.
A Ruby code quality reporter.
An opinionated ruby formatter, intended to be used via the command line as a text-editor plugin, to autoformat files on save or on demand.
A SkunkScore Calculator for Ruby Code -- Find the most complicated code without test coverage!
A fast, powerful type checker designed for Ruby.
Ruby Style Guide, with linter & automatic code fixer
Gradual Typing for Ruby.
C2Rust helps you migrate C99-compliant code to Rust. The translator (or transpiler) produces unsafe Rust code that closely mirrors the input C code.
Find unused dependencies in Cargo.toml. It either prints out a "unused crates" line listing the crates, or it prints out a line saying that no crates were unused.
Audit Cargo.lock for crates with security vulnerabilities reported to the RustSec Advisory Database.
A cargo plugin for linting your dependencies. It can be used either as a command line too, a Rust crate, or a Github action for CI. It checks for valid license information, duplicate crates, security vulnerabilities, and more.
Cargo subcommand to show result of macro expansion and #[derive] expansion applied to the current crate. This is a wrapper around a more verbose compiler command.
A cargo plugin for analysing the usage of unsafe Rust code Provides statistical output to aid security auditing
Scan your Rust crate releases for semver violations. It can be used either directly via the CLI, as a GitHub Action in CI, or via release managers like release-plz. It found semver violations in more than 1 in 6 of the top 1000 most-downloaded crates on crates.io.
cargo subcommand showing the assembly, LLVM-IR and MIR generated for Rust code
Checks all your documentation for spelling and grammar mistakes with hunspell (ready) and languagetool (preview)
A code linter to catch common mistakes and improve your Rust code.
Web application (WASM) to render a diff between Rust crate versions.
A tool for running Rust lints from dynamic libraries. Dylint makes it easy for developers to maintain their own personal lint collections.
The Kani Rust Verifier is a bit-precise model checker for Rust. Kani is particularly useful for verifying unsafe code blocks in Rust, where the "unsafe superpowers" are unchecked by the compiler. Kani verifies:
Statically detects Rust deadlocks bugs. It currently detects two common kinds of deadlock bugs: doublelock and locks in conflicting order. It will print bugs in JSON format together with the source code location and an explanation of each bug.
Rust Memory Safety & Undefined Behavior Detection. It is capable of analyzing single Rust packages as well as all the packages on crates.io.
Supports functionality such as 'goto definition', type inference, symbol search, reformatting, and code completion, and enables renaming and refactorings.
Audit Rust binaries for known bugs or security vulnerabilities. This works by embedding data about the dependency tree (Cargo.lock) in JSON format into a dedicated linker section of the compiled executable.
A tool for formatting Rust code according to style guidelines.
RustViz is a tool that generates visualizations from simple Rust programs to assist users in better understanding the Rust Lifetime and Borrowing mechanism. It generates SVG files with graphical indicators that integrate with mdbook to render visualizations of data-flow in Rust programs.
copyright: — Helps you understand and maintain a scalable software architecture. To do so, it generates a interactive, nested dependency graph out of the source code. You can choose the level of details and get the portion of your codebase that matters to you.
Database DevSecOps platform with a built-in SQL Review engine that lints schema migrations and queries against 100+ configurable rules — naming conventions, anti-patterns, and safety checks — across MySQL, PostgreSQL, Oracle, SQL Server, Snowflake, and more.
dbcritic finds problems in a database schema, such as a missing primary key constraint in a table.
More than 1,300 rules to analyze SQL queries. Takes an SQL schema definition and the query source code to generate improvement recommendations. Detects code smells, unused indexes, unused tables, views, materialized views, and more.
Spot vulnerabilities in postgres extension scripts. Finds unsafe search_path usage and unsafe object creation in PostgreSQL extension scripts or any other PostgreSQL SQL code.
Polyglot SQL compiler and linter that generates type-safe code from SQL with schema-aware linting.
Multiple dialect SQL linter and formatter.
Simple SQL linter.
Linter for PostgreSQL, focused on migrations. Prevents unexpected downtime caused by database migrations and encourages best practices around Postgres schemas and SQL.
T-SQL-specific linter.
copyright: — Code analysis for PowerBuilder, Oracle, and SQL Server Explores, analyzes, and documents Code
Scala compiler plugin for static code analysis.
A flexible Scala code linting tool.
A shell parser, formatter, and interpreter with bash support; includes shfmt
ShellCheck, a static analysis tool that gives warnings and suggestions for bash/sh shell scripts.
A syntax highlighter and a tool to semi-automate the rewriting of scripts to ShellCheck conformance, mainly focused on quoting.
A library and command-line formatting tool for reformatting Swift code.
A tool to enforce Swift style and conventions.
A Tcl formatting and static check program (can prettify the program, minimise, obfuscate or just sanity check it).
A static syntax checker for Tcl.
A static syntax analysis module (as part of TDK).
Linter for Angular projects
Rust-based static analysis for TypeScript projects
CLI to generate an interactive graph of functions and calls from your TypeScript files
TypeScript language extension for eslint.
TypeScript-first schema validation with static type inference. The goal is to eliminate duplicative type declarations. With Zod, you declare a validator once and Zod will automatically infer the static TypeScript type. It is easy to compose simpler types into complex data structures.
A Language Server Protocol implementation for Verilog and SystemVerilog, including lint capabilities.
A tool which converts Verilog to a cycle-accurate behavioral model in C++ or SystemC. Performs lint code-quality checks.
Verilog HDL/SystemVerilog/Bluespec SystemVerilog support for VS Code. Provides syntax highlighting and Linting support from Icarus Verilog, Vivado Logical Simulation, Modelsim and Verilator
Analyzes a binary's call graph to profile code size. The goal is to slim down wasm binary size.
WebAssembly Language Tools aims to provide and improve the editing experience of WebAssembly Text Format. It also provides an out-of-the-box formatter (a.k.a. pretty printer) for WebAssembly Text Format.
A binary static analysis tool that provides security and correctness results for Windows portable executables.
copyright: — Tool to analyze source code and binaries for reusable code, necessary licenses and potential security aspects.
Ever wondered what's making your binary big? Bloaty McBloatface will show you a size profile of the binary so you can understand what's taking up space inside. Bloaty performs a deep analysis of the binary. Using custom ELF, DWARF, and Mach-O parsers, Bloaty aims to accurately attribute every byte…
cwe_checker finds vulnerable patterns in binary executables.
A software reverse engineering (SRE) suite of tools developed by NSA's Research Directorate in support of the Cybersecurity mission
copyright: — macOS and Linux reverse engineering tool that lets you disassemble, decompile and debug applications. Hopper displays the code using different representations, e.g. the Control Flow Graph, and the pseudo-code of a procedure. Supports Apple Silicon.
copyright: — Binary code analysis tool.
copyright: — Decompile and debug binary code. Break down and analyze document files. Android Dalvik, MIPS, ARM, Intel x86, Java, WebAssembly & Ethereum Decompilers.
copyright: — Hexadecimal editor and disassembler for malware analysis and binary file inspection. Supports over 50 file formats and multiple CPU architectures (x86/x64, MIPS, .NET, Python, VB p-code). Features rapid analysis, embedded file extraction, Yara signature scanning, anomaly detection,…
A static analyzer, which checks portable executables for malicious content.
Static Linker/Compiler/Tool detector for Windows, Linux and MacOS.
IDA Pro headless plugin that locates calls to potentially insecure API functions in a binary file.
Fast and lightweight x86/x86-64 disassembler library
Linter / Analyzer for Makefiles.
A verifier for FreeBSD and DragonFlyBSD port directories.
Helps you catch problems in your HTML/CSS/SVG
A tool for transforming styles with JS plugins. These plugins can lint your CSS, support variables and mixins, transpile future CSS syntax, inline images, and more.
Analytics for CSS, part of Project Wallace.
Linter for SCSS/CSS files.
Linting dotenv files like a charm.
Lightning-fast linter for .env files. Written in Rust
Checks playbooks for practices and behaviour that could potentially be improved.
Check local CloudFormation templates against policy-as-code rules and generate rules from existing templates.
AWS Labs CloudFormation linter.
Static analysis tool for Terraform files (tf>=v0.12), preventing cloud misconfigs at build time.
Cookstyle is a linting tool based on the RuboCop Ruby linting tool for Chef cookbooks.
Tool to check the validity of Puppet metadata.json files.
A lightweight, compliance- and security focused, BDD test framework against Terraform.
Collection of security and best practice tests for static code analysis of Terraform templates.
A Terraform linter for detecting errors that can not be detected by terraform plan.
Terraform static analysis tool that prevents potential security issues by checking cloud misconfigurations at build time and directly integrates with the HCL parser for better results. Checks for violations of AWS, Azure and GCP security best practice recommendations.
Vulnerability Static Analysis for Containers.
Container Image Linter for Security helping build the Best-Practice Docker Image. Scans Docker images for security vulnerabilities and CIS Benchmark compliance. Checks for secrets, credential exposure, and security best practices. Provides multiple severity levels (FATAL, WARN, INFO) and supports…
Vulnerability scanner for container images and filesystems. Developed by Anchore, it scans container images, directories, and archives for known vulnerabilities. Supports multiple image formats, SBOM integration, and VEX (Vulnerability Exploitability eXchange) for accurate vulnerability…
A smarter Dockerfile linter that helps you build best practice Docker images.
Krane is a simple Kubernetes RBAC static analysis tool. It identifies potential security risks in K8s RBAC design and makes suggestions on how to mitigate them. Krane dashboard presents current RBAC security posture and lets you navigate through its definition.
Suite of automated audit tools to examine the configuration and known vulnerabilities following the NIST-certified Security Content Automation Protocol (SCAP).
copyright: — Container native application protection to provide visibility and control of containerized applications.
copyright: — A secure DevOps platform for cloud and container forensics. Built on an open source stack, Sysdig provides Docker image scanning and created Falco, the open standard for runtime threat detection for containers, Kubernetes and cloud.
Agent-less Linux vulnerability scanner based on information from NVD, OVAL, etc. It has some container image support, although is not a container specific tool.
Static checker for GitHub Actions workflow files. Provides an online version.
The open and extensible static analysis platform, for everyone.
copyright: — Codecov is a company that provides code coverage tools for developers and engineering leaders to gain visibility into their code coverage. They offer flexible and unified reporting, seamless coverage insights, and robust coverage controls. Codecov supports over 20 languages and is…
copyright: — AI-powered code review tool that helps developers write better code faster. CodeRabbit provides automated code reviews, identifies security vulnerabilities, and suggests code improvements. It integrates with GitHub and GitLab.
copyright: — Code review as a service with built-in static analysis. Increase velocity and reduce technical debt through quality code review by expert engineers backed by best-in-class automation.
Static analysis for GitHub Actions workflows, detecting insecure CI/CD patterns such as excessive token permissions, template injection risks, credential persistence, and unsafe workflow references.
Official linter for Deno.
Cloud (IaC) Security plugin for JetBrains IDEs. Performs real-time inspections of Docker & Kubernetes IaC with 50+ rules based on Docker image/build security best practices, Kubernetes Pod Security Standards, and NSA/CISA Kubernetes Hardening Guidance.
Linter for bitbake recipes used in open-embedded and YOCTO
Accessibility engine for automated Web UI testing. Tests HTML against WCAG 2.0, 2.1, and 2.2 guidelines. Used by Google Lighthouse, Microsoft Accessibility Insights, and thousands of organizations worldwide.
Offline HTML5 validator.
A Static Code Analysis Tool for HTML.
Automated accessibility testing tool that runs HTML CodeSniffer or axe-core from the command line. Supports CI/CD integration, multiple reporters, and testing against WCAG 2.1 AA standards.
A flexible JSON/YAML linter, with out-of-the-box support for OpenAPI v2/v3 and AsyncAPI v2.
ct is the tool for testing Helm charts. It is meant to be used for linting and testing pull requests. It automatically detects charts changed against the target branch.
Clusterlint queries live Kubernetes clusters for resources, executes common and platform specific checks against these resources and provides actionable feedback to cluster operators. It is a non invasive tool that is run externally. Clusterlint does not alter the resource configurations.
Hunt for security weaknesses in Kubernetes clusters.
KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best practices.
Static code analysis of your Kubernetes object definitions.
A fast Kubernetes manifests validator with support for custom resources.
A tool for finding common mistakes in LaTeX documents.
A Language Server Protocol implementation for TeX/LaTeX, including lint capabilities.
Node.js -based style checker and lint tool for Markdown/CommonMark files.
CommonMark compliant Markdown formatter
A tool to check Markdown files and flag style issues.
Format markdown code blocks using your favorite code formatters.
Pluggable Markdown code style linter written in JavaScript.
textlint is an open source text linting utility written in JavaScript.
Run static analysis on Android projects.
Static taint analysis tool for Android applications.
copyright: — Enterprise vulnerability scanner for Android and iOS apps. It allows app owners and developers to secure each new version of a mobile app by integrating Oversecured into the development process.
Redex provides a framework for reading, writing, and analyzing .dex files, and a set of optimization passes that use this framework to improve the bytecode. An APK optimized by Redex should be smaller and faster.
Scan Nix files for dead code (unused variable bindings)
Lints and suggestions for the Nix programming language. "statix check" highlights antipatterns in Nix code. "statix fix" can fix several such occurrences.
Lint an npm or yarn lockfile to analyze and detect security issues
Static analysis tool for Debian packages.
Tool for checking common errors in rpm packages.
Promformat is a PromQL formatter written in Python.
Provides a CLI linter that enforces good API design choices and structure
Pluggable linter and fixer to enforce Protocol Buffer style and conventions.
An enterprise friendly way of detecting and preventing secrets in code. It does this by running periodic diff outputs against heuristically crafted regex statements, to identify whether any new secret has been committed. This way, it avoids the overhead of digging through all git history, as well…
A SAST tool for detecting hardcoded secrets like passwords, api keys, and tokens in git repos.
copyright: — HasMySecretLeaked is a project from GitGuardian that aims to help individual users and organizations search across 20 million exposed secrets to verify if their developer secrets have leaked on public repositories, gists, and issues on GitHub projects.
Attack surface detector that identifies endpoints by static analysis.
copyright: — Identifies code flaws and detects vulnerabilities to prevent web attacks. Demonstrates remote code execution by presenting possible exploits.
Security Scorecards - Security health metrics for Open Source
Find credentials all over the place TruffleHog is an open source secret-scanning engine that resolves exposed secrets across your company’s entire tech stack.
A general purpose network security scanner with an extensible plugin system for detecting high severity RCE-like vulnerabilities with high confidence. Custom detectors for finding vulnerabilities (e.g. open APIs) can be added.
copyright: — MythX is an easy to use analysis platform which integrates several analysis methods like fuzzing, symbolic execution and static analysis to find vulnerabilities with high precision. It can be integrated with toolchains like Remix or VSCode or called from the command-line.
Static analysis framework that runs a suite of vulnerability detectors, prints visual information about contract details, and provides an API to easily write custom analyses.
Solhint is an open source project created by https://protofire.io. Its goal is to provide a linting utility for Solidity code.
Tool for writing clean and consistent HAML.
Configurable tool for analyzing Slim templates.
Checks YAML files for syntax validity, key repetition and cosmetic problems such as lines length, trailing spaces, and indentation.
A set of utilities for working with PO files to ease development and improve quality.
Check code for common misspellings.
Style and grammar checker for 25+ languages. It finds many errors that a simple spell checker cannot detect.
A spell-checker that groups possible misspellings and shows them in their contexts.
A linter for English prose with a focus on writing style instead of grammar.
A syntax-aware linter for prose built with speed and extensibility in mind.
copyright: — Validator and linter for VAST XML ad tags. Checks wrappers and inline tags against the IAB VAST 2.0-4.3 specification and can auto-fix deterministic issues.
checks if your commit messages meet the conventional commit format
Linter for ABAP, written in TypeScript.
Enhances the SAP Code Inspector with new and customizable checks.
copyright: — Provide code verification that proves the absence of overflow, divide-by-zero, out-of-bounds array access, and certain other run-time errors in source code.
copyright: — Static analysis and formal verification toolset for Ada.
Asynchronous Lint Engine for Vim and NeoVim with support for many languages.
Based on IntelliJ IDEA, and comes bundled with tools for Android including Android Lint.
copyright: — Static analysis for C/C++/C#, PHP and Java.
copyright: — Commercial Static Code Analysis which generates exploits to verify vulnerabilities.
Creates reports of over 400 rule patterns for feature detection (e.g. the use of cryptography or version control in apps).
Unit test your Java or Kotlin architecture.
Multi-language maintainability analyzer. Computes cyclomatic and cognitive complexity, Halstead volume, afferent/efferent coupling and maintainability index, detects communities in the dependency graph, and generates an explorable HTML report plus JSON, Markdown, SARIF and OpenMetrics output.…
ast-grep is a powerful tool designed for managing code at scale using Abstract Syntax Trees (AST). Think of it as a hybrid of grep, eslint, and codemod, with the ability to search, lint, and rewrite code based on its structure rather than plain text. It supports multiple languages and is designed…
A linter and formatter to help you to improve copywriting, correct spaces, words, punctuations between CJK (Chinese, Japanese, Korean).
copyright: — Tracks down error-prone code locations, style violations, cloned or dead code, cyclic dependencies and more for C/C++, C#/.NET, Java and Ada 83/Ada 95.
Open-Source static code analysis tool to discover, filter and prioritize security risks and vulnerabilities leading to sensitive data exposures (PII, PHI, PD). Highly configurable and easily extensible, built for security and engineering teams.
copyright: — Better Code Hub checks your GitHub codebase against 10 engineering guidelines devised by the authority in software quality, Software Improvement Group.
A toolchain for web projects, aimed to provide functionalities to maintain them. Biome formats and lints code in a fraction of a second. It is the successor to Rome. It is designed to eventually replace Biome is designed to eventually replace Babel, ESLint, webpack, Prettier, Jest, and others.
A language-agnostic linter that keeps code, documentation, and configuration in sync and enforces strict formatting and validation rules.
copyright: — Commercial Static Code Analysis which runs locally, but uploads the results to its cloud for presentation.
copyright: — Commercial Static Code Analysis which doesn't require pre-compilation.
A classpath and module path scanner for querying or visualizing class metadata or class relatedness.
copyright: — AI-powered code reviews for Salesforce. Secure your developments, enforce best practice and control your technical debt in real-time.
copyright: — Structural source code analyzer by NASA's Jet Propulsion Laboratory.
copyright: — CI/CD-agnostic DevSecOps platform which combines industry-leading fuzzing engines for finding bugs and visualizing code coverage
Opensource Static Code Analysis for security teams with Inter file dataflow taint analysis. Built for finding vulnerabilities, advanced structural search, derive insights and supports MCP server.
Builds knowledge graphs from multi-language codebases using Tree-sitter AST parsing and stores them in Memgraph. Supports 11 programming languages with a unified graph schema and enables natural language querying and editing of code structure and relationships. Functions as an MCP server for AI…
copyright: — Automated code review tool integrates with GitHub, Bitbucket and GitLab (even self-hosted). Available for JavaScript, TypeScript, Python, Ruby, Go, PHP, Java, Docker, and more. (open-source free)
copyright: — Automated Code Analysis for repos on GitHub or BitBucket.
copyright: — Automated code analysis tool to deal with technical depth. Integrates with Bitbucket and Gitlab. (free for Open Source Projects)
Deep code analysis - semantic queries and dataflow for several languages with VSCode plugin support.
Ecosystem for structural matching JavaScript and TypeScript code. Offers search tool that understands code structure. Available as CLI tool and Visual Studio Code extension. It helps to search code faster and more accurately making you workflow more effective. Soon it will offer ESLint plugin to…
copyright: — Code creation, debugging, navigation, refactoring, analysis and visualization tools that use the Roslyn engine in Visual Studio 2015 and up.
copyright: — Code Quality and Security for Salesforce Developers. Made exclusively for the Salesforce platform, CodeScan’s code analysis solutions provide you with total visibility into your code health.
copyright: — CodeScene is a quality visualization tool for software. Prioritize technical debt, detect delivery risks, and measure organizational aspects. Fully automated.
copyright: — Advanced, whole program, deep path, static analysis of C, C++, Java and C# with easy-to-understand explanations and code and path visualization.
copyright: — Automated Code Reviews and Technical Debt management platform that supports 12+ languages.
copyright: — Corgea is an AI-powered SAST scanner that helps developers find and fix insecure code. It finds business logic flaws, broken authentication, API vulnerabilities, and more with little false positives. Additionally, it automatically writes security fixes for them to approve. Corgea…
copyright: — Synopsys Coverity supports 20 languages and over 70 frameworks including Ruby on rails, Scala, PHP, Python, JavaScript, TypeScript, Java, Fortran, C, C++, C#, VB.NET.
A Github Action for linting C/C++ code integrating clang-tidy and clang-format to collect feedback provided in the form of thread comments and/or annotations.
copyright: — In-depth static analysis to find issues in verticals of bug risks, security, anti-patterns, performance, documentation and style. Native integrations with GitHub, GitLab and Bitbucket. Less than 5% false positives.
copyright: — Deleaker is a memory leak detection tool for C++, .NET, and Delphi, integrating with Visual Studio, Qt Creator, and RAD Studio or running as a standalone application. It helps developers find and fix memory, GDI, and handle leaks efficiently.
Analyses the comprehensive dependencies of code elements for Java, C/C++, Ruby.
copyright: — Free, anonymous SCA + SAST scanner. SCA: scans npm, PyPI, Maven, Go, Cargo, Ruby, NuGet dependencies for CVEs (OSV/KEV/EPSS), typosquats and supply-chain risk. SAST: pattern + taint analysis for 15 languages, 300+ rules. No account, no source upload. Available as a web tool,…
copyright: — Multi-language Static Application Security Testing (SAST) platform that detects critical vulnerabilities, including hardcoded secrets, weak cryptography, backdoors, SQL injections, insecure configurations, etc.
Regex-based static analysis tool for Visual Studio, VS Code, and Sublime Text - C/C++, C#, PHP, ASP, Python, Ruby, Java, and others.
Linter for dangerous Postgres migration patterns in Diesel and SQLx. Prevents downtime caused by unsafe schema changes.
A code formatter for .NET. Preferences will be read from an .editorconfig file, if present, otherwise a default set of preferences will be used. At this time dotnet-format is able to format C# and Visual Basic projects with a subset of supported .editorconfig options.
copyright: — Intelligent software analytics platform that identifies design issues, code issues, duplication and metrics. Supports Java, C, C++, C#, JavaScript, TypeScript, Python, Go, Kotlin and more.
Emerge is a source code and dependency visualizer that can be used to gather insights about source code structure, metrics, dependencies and complexity of software projects. After scanning the source code of a project it provides you an interactive web interface to explore and analyze your project…
copyright: — Enforster AI performs Contextual Code Security SAST, leveraging LLMs and artificial intelligence to reduce and enrich the detection of Logic Flaws, Secrets, Data leaks, Supply chain and technical vulnerabilities.
A JavaScript compiler and TypeScript checker written in Rust with a focus on static analysis and runtime performance. Ezno's type checker is built from scratch. The checker is fully compatible with TypeScript type annotations and can work without any type annotations at all.
Rust-native static analysis for JavaScript and TypeScript. Maps a repository as one dependency graph to find unused code and structural problems across file boundaries. Runs from the CLI or GitHub Actions, with VS Code, LSP, MCP, and Node API integrations.
The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
copyright: — A commercial static analysis platform that supports the scanning of C/C++, C#, VB.NET, VB6, ABAP/BSP, ActionScript, Apex, ASP.NET, Classic ASP, VB Script, Cobol, ColdFusion, HTML, Java, JS, JSP, MXML/Flex, Objective-C, PHP, PL/SQL, T-SQL, Python (2.6, 2.7), Ruby (1.9.3), Swift, Scala,…
The Code Explorer mode in Freeplane is designed for analyzing the structure and dependencies of code compiled to JVM class files. It also allows displaying ArchUnit test results directly in Freeplane, if Freeplane is running and ArchUnit detects rule violations during the tests.
Regexp based customizable linter.
Grep rough audit - source code auditing tool.
copyright: — Commercial Static Code Analysis.
Comments on style violations in GitHub pull requests. Supports Coffeescript, Go, HAML, JavaScript, Ruby, SCSS and Swift.
A static analyzer for Java, C and Objective-C
AI agent security scanner. Detects behavioral vulnerabilities (prompt injection, infinite loops, token bombing, SQL injection via LLM) across 11 framework adapters including LangChain, CrewAI, and pydantic-ai. Audits MCP servers. Maps findings to EU AI Act, OWASP LLM Top 10, and NIST AI RMF.
Joern is a platform for analyzing source code, bytecode, and binary executables. It generates code property graphs (CPGs), a graph representation of code for cross-language code analysis. Code property graphs are stored in a custom graph database. This allows code to be mined using search queries…
jQAssistant is a plugin based software analytics platform which allows scanning code structures and metadata from repositories into a Neo4j graph database. The gathered data can be used for ad-hoc exploration using queries, visualization or defining rules for continuous architecture validation.
Copy/paste detector for programming source code. Finds duplicated blocks in 200+ file formats — JavaScript, TypeScript, Python, Java, C#, C/C++, Go, Rust, PHP, Ruby and more — using token-based detection. Supports configurable thresholds and ignore patterns, git blame integration, and reporters…
Keploy is an open-source testing platform that helps developers automate and streamline their testing process. It provides API, and integration testing agents, generating tests, mocks/stubs for APIs that actually work. Additionally, Keploy offers an AI-powered Unit Testing Agent that generates…
copyright: — Identify and remediate cyber threats in a blazingly fast, collaborative environment, with seamless integration in your SDLC. Python, C\C++, Java, C#, PHP and more.
copyright: — Quality and Security Static analysis for C/C++, Java and C#.
copyright: — Find security vulnerabilities, variants, and critical code quality issues using CodeQL queries over source code. Automatic PR code review; free for open source. Formerly semmle. It supports public Git repositories hosted on Bitbucket Cloud, GitHub.com, GitLab.com.
Lizard is an extensible Cyclomatic Complexity Analyzer for many programming languages including C/C++ (doesn't require all the header files or Java imports). It also does copy-paste detection (code clone detection/code duplicate detection) and many other forms of static code analysis. Counts lines…
Mega-Linter can handle any type of project thanks to its 70+ embedded Linters, its advanced reporting, runnable on any CI system or locally, with assisted installation and configuration, able to apply formatting and fixes
copyright: — Mobb is a trusted, automatic vulnerability fixer that secures applications, reduces security backlogs, and frees developers to focus on innovation. Mobb is free for open-source projects.
A static analyzer designed to easily reuse abstract domains across widely different languages (such as C and Python).
Static analysis tool for NestJS applications. Detects anti-patterns across security, performance, correctness, and architecture with 30+ built-in rules. Outputs a 0-100 health score. Includes module graph visualization, endpoint dependency graphs, and database schema analysis. CLI and VS Code…
Deterministic code transformation tool using AST parsing and rule-based transformations. Automatically fixes 50+ issues including accessibility violations, hydration errors, React 19/Next.js 16 migrations, and configuration updates. Features 5-step fail-safe orchestration to ensure zero breaking…
A static source code analysis tool to improve quality and reduce defects for C, C++ and Objective-C.
copyright: — Commercial Static Code Analysis system doesn't require building the source code or pre-compilation.
OpenRewrite fixes common static analysis issues reported through Sonar and other tools using a Maven and Gradle plugin or the Moderne CLI.
OpenStaticAnalyzer is a source code analyzer tool, which can perform deep static analysis of the source code of complex systems.
Open-source taint analysis engine for Java and Kotlin applications, formerly Seqra. Tracks data flow across function boundaries to find security vulnerabilities, with Spring support, YAML rules, and CI integrations.
The Oxidation Compiler is creating a suite of high-performance tools for the JavaScript / TypeScript language re-written in Rust.
copyright: — Automated Software Testing Solutions for unit-, API-, and web UI testing. Complies with MISRA, OWASP, and others.
Facebook's tools for code analysis, visualizations, or style-preserving source transformation for many languages.
copyright: — Pixeebot finds security and code quality issues in your code and creates merge-ready pull requests with recommended fixes.
A source code analyzer for Java, Salesforce Apex, Javascript, PLSQL, XML, XSL and others.
A framework for managing and maintaining multi-language pre-commit hooks.
Precaution is a static analysis security tool (SAST) designed to find potentially critical vulnerabilities in source code prior to production. It is available as a CLI, GitHub Action, and GitHub App.
An opinionated code formatter.
Quick automated code review of your changes. Supports more than 40 runners for various languages, including Clang, Elixir, JavaScript, PHP, Ruby and more.
Pluggable and configurable code transformer with built-in eslint, babel plugins support for js, jsx typescript, flow, markdown, yaml and json.
copyright: — PVS-Studio is a SAST tool that enhances code quality, security, and safety. Supported languages: C, C++, C#, Java, Go, JavaScript and TypeScript. Works on Windows, macOS, Linux. Supports intermodular, incremental, data flow analysis, taint analysis. Provides compliance with OWASP TOP…
copyright: — Identify vulnerabilities that are unique to your code base before they reach production. Leverages the Code Property Graph (CPG) to run its analyses concurrently in a single graph of graphs. Automatically finds business logic flaws in dev like hardcoded secrets and logic bombs
A static file linter that allows you to write custom rules using regular expressions (RegEx).
Deterministic, zero-LLM code-health analysis. Scores every file 1-10 for defect risk, maintainability, and performance from 25 markers: McCabe complexity, LCOM4 cohesion, god classes, Rabin-Karp clone detection, change entropy, and untested hotspots. Adds a dependency graph, dead-code detection,…
copyright: — Extends Visual Studio with on-the-fly code inspections for C#, VB.NET, ASP.NET, JavaScript, TypeScript and other technologies.
Dependency analysis and optimization toolkit for modern JavaScript and TypeScript projects. Trace imports, identify circular dependencies, find unused code, clean node modules.
copyright: — A static source code analyser for vulnerabilities in PHP scripts.
Roslyn-based implementation of FxCop analyzers.
Validate and auto-generate TypeScript types from raw SQL queries in PostgreSQL. SafeQL is an ESLint plugin for writing SQL queries in a type-safe way.
copyright: — Check the Android Source code thoroughly to uncover and address potential security concerns and vulnerabilities. Static application security testing (Static Code Analysis) tool Online
Semantic version control CLI that provides entity-level diffs, blame, and impact analysis on top of git. Uses tree-sitter to parse 26 languages and builds a cross-file dependency graph with structural hashing. Commands include sem diff, sem blame, sem graph, and sem impact for blast-radius…
A fast, open-source, static analysis tool for finding bugs and enforcing code standards at editor, commit, and CI time. Its rules look like the code you already write; no abstract syntax trees or regex wrestling. Supports 17+ languages.
copyright: — Quickly find and remediate high-priority security issues. Semgrep Supply Chain prioritizes the 2% of vulnerabilities that are reachable from your code.
copyright: — Sigrid helps you to improve your software by measuring your system's code quality, and then compares the results against a benchmark of thousands of industry systems to give you concrete advice on areas where you can improve.
A tool that finds similarities between or within files to support you encountering DRY principle violations.
Dead code detection, security scanning, secrets detection, and code quality analysis for Python, TypeScript, and Go. Framework-aware analysis with 98% recall. Includes CI/CD GitHub Action, VS Code extension, and MCP server for AI agent integration.
copyright: — Snyk Code finds security vulnerabilities based on AI. Its speed of analysis allow us to analyse your code in real time and deliver results when you hit the save button in your IDE. Supported languages are Java, JavaScript, Python, PHP, C#, Go and TypeScript. Integrations with GitHub,…
copyright: — SonarQube Cloud enables your team to deliver clean code consistently and efficiently with a code review tool that easily integrates into the cloud DevOps platforms and extend your CI/CD workflow. SonarQube Cloud provides a free plan.
SonarQube for IDE (formerly SonarLint) is a free IDE extension available for IntelliJ, VS Code, Visual Studio, and Eclipse, to find and fix coding issues in real-time, flagging issues as you code, just like a spell-checker. More than a linter, it also delivers rich contextual guidance to help…
SonarQube empowers development teams with a code quality and security solution that deeply integrates into your enterprise environment; enabling you to deploy clean code consistently and reliably. SonarQube provides a free and open source Community Build.
copyright: — Reports known vulnerabilities in common dependencies and recommends updated packages to minimize breaking changes
copyright: — Suite of static analysis tools consisting of the three components Sotoarc (Architecture Analysis), Sotograph (Quality Analysis), and Sotoreport (Quality report). Helps find differences between architecture and implementation, interface violations (e.g. external access of private parts…
copyright: — Static Code Analysis for C/C++, Java, C#, Python, and RPG III and RPG IV versions (including free-form).
Performs static analysis on raw SQL queries in your Go code base to surface potential runtime errors. It checks for SQL syntax error, identifies unsafe queries that could potentially lead to SQL injections makes sure column count matches value count in INSERT statements and validates table- and…
copyright: — Static Reviewer executes code checks according to the most relevant Secure Coding Standards, OWASP, CWE, CVE, CVSS, MISRA, CERT, for 40+ programming languages, using 1000+ built-in validation rules for Security, Deadcode & Best Practices Available a module for Software Composition…
Combination of multiple linters to install as a GitHub Action.
copyright: — Static code analysis tool for Java,C,C++,C#,Go.
copyright: — Static and dynamic analysis tool supporting more than 25 languages and direct IDE integration. Free hosting for Open Source projects available on request. Free academic licenses available.
Tencent Cloud Code Analysis (TCA for short, code-named CodeDog inside the company early) is a comprehensive platform for code analysis and issue tracking. TCA consist of three components, server, web and client. It integrates of a number of self-developed tools, and also supports dynamic…
Multi-language linter targeting anti-patterns that appear disproportionately in AI-generated code: duplicated blocks across files, excessive nesting, magic numbers, Single Responsibility violations, and linter suppressions added without justification. Covers Python, TypeScript, JavaScript and Rust…
Vulnerability Scanner and Risk Evaluation for containers, serverless and hosts at runtime. ThreatMapper generates runtime BOMs from dependencies and operating system packages, matches against multiple threat feeds, scans for unprotected secrets, and scores issues based on severity and…
Linter for integrating annotated TODOs with your issue trackers
A Simple and Comprehensive Vulnerability Scanner for Containers and other Artifacts, Suitable for CI. Trivy detects vulnerabilities of OS packages (Alpine, RHEL, CentOS, etc.) and application dependencies (Bundler, Composer, npm, yarn, etc.). Checks containers and filesystems.
copyright: — Modern repositories include many technologies, each with its own set of linters. With 30+ linters and counting, Trunk makes it dead-simple to identify, install, configure, and run the right linters, static analyzers, and formatters for all your repos.
copyright: — Code visualization tool that provides code analysis, standards testing, metrics, graphing, dependency analysis and more for Ada, VHDL, and others.
Universal code beautifier with a GitHub app. Supports HTML, CSS, JavaScript, TypeScript, JSX, Vue, C++, Go, Objective-C, Java, Python, PHP, GraphQL, Markdown, and more.
copyright: — Code review tool with static code analysis and code-aware navigation for Java, PHP, JavaScript and Kotlin.
copyright: — Find flaws in binaries and bytecode without requiring source. Support all major programming languages: Java, .NET, JavaScript, Swift, Objective-C, C, C++ and more.
JavaScript decompiler that turns bundled, minified, transpiled production code back into readable modules. Unpacks webpack, esbuild, Metro, Browserify, SystemJS, and AMD/UMD bundles, then reverses minifier artifacts and Babel/TypeScript/SWC helpers (async/await, classes, optional chaining, and…
Static analysis capabilities for Java bytecode and related languages and for JavaScript.
Entity-level semantic merge driver for git. Resolves false conflicts that line-based merge produces when independent changes touch the same file. Parses functions and classes via tree-sitter, matches by name, and merges at the entity level. Benchmarked at 100% clean merges vs git's 48% on a…
copyright: — WhiteHat Scout (for Developers) combined with WhiteHat Sentinel Source (for Operations) supporting WhiteHat Top 40 and OWASP Top 10.
copyright: — XCode provides a pretty decent UI for Clang's static code analyzer (C/C++, Obj-C).
copyright: — Xygeni is a comprehensive Software Supply Chain Security platform. It provides Advanced SAST with AI-powered remediation, Software Composition Analysis (SCA) with real-time malware detection, Infrastructure as Code (IaC) scanning, and Secrets detection to ensure end-to-end code…
ggshield is a CLI application that runs in your local environment or in a CI environment to help you detect more than 350+ types of secrets, as well as other potential security vulnerabilities or policy breaks affecting your codebase.
Multi-language linter targeting anti-patterns that appear disproportionately in AI-generated code: duplicated blocks across files, excessive nesting, magic numbers, Single Responsibility violations, and linter suppressions added without justification. Covers Python, TypeScript, JavaScript and Rust…
Static linter for natural-language instructions that control AI agents. Detects ambiguous tool descriptions, missing limits, conflicting directives, and schema gaps in local files and CI without model or network calls.
Configurable linter for the files that steer AI coding agents, including skills, plugins, instruction files, hooks, and related configuration. Detects structural, content-quality, and security issues and provides deterministic autofixes, baselines, and CI-ready output.
Security assessment for your OpenClaw agent environment. Flags misconfigurations and risky skills — prompt injection, permission escalation, data exfiltration — and the chained attack paths between them, across gateway config, tool permissions, MCP servers, and plugins.
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations in your infrastructure-as-code. Supports Terraform, Kubernetes, Docker, AWS CloudFormation and Ansible
copyright: — Ansible Playbook Scanning Tool that analyzes and offers recommendations for your playbooks.
Packj (pronounced package) is a command line (CLI) tool to vet open-source software packages for "risky" attributes that make them vulnerable to supply chain attacks. This is the tool behind our large-scale security analysis platform Packj.dev that continuously vets packages and provides free…
Independent comparison of 30+ static analysis security testing tools with features, pricing, and alternatives
A collection of linters in github collections
A collection of PHP linters in github collections
A collection of tools and libraries for working with Go code, including linters and static analysis
An introduction to static code analysis
List of tools maintained by the Open Web Application Security Project
A reviewed list of useful PHP static analysis tools
A list of tools for static code analysis.
hesreallyhim/awesome-claude-code
A hand-picked collection of the finest of resources for the most awesome of agents, Claude Code, the undisputed champion of coding companions, from the unstoppable team…
VoltAgent/awesome-agent-skills
A curated collection of 1000+ agent skills from official dev teams and the community, compatible with Claude Code, Codex, Gemini CLI, Cursor, and more.
josephmisiti/awesome-machine-learning
A curated list of awesome Machine Learning frameworks, libraries and software.
EthicalML/awesome-production-machine-learning
A curated list of awesome open source libraries to deploy, monitor, version and scale your machine learning
academic/awesome-datascience
:memo: An awesome Data Science repository to learn and apply for real world problems.
kyrolabs/awesome-langchain
😎 Awesome list of tools and projects with the awesome LangChain framework